✦ProjectOnUs
Workflow Construction Pilot Pricing
Sign in Start free
Legal & trust

Privacy policy

Last updated September 28, 2026

This policy explains how ProjectOnUs (“ProjectOnUs”, “we”) handles personal data in the ProjectOnUs apps (Projects and Documents) and on this website. Questions or requests: privacy@projectonus-delivered.com.

Who is responsible

Your organization (our customer) decides what is uploaded to ProjectOnUs and who can see it. For that content, your organization is the controller and we are its processor: we handle it only to provide the service, under our Data Processing Agreement. For account and billing information about our customers, and for this website, we are the controller.

What we collect

  • Account data — name and email address from your Google or Microsoft sign-in; your role and organizations; the invitations you send or receive.
  • Content your organization adds — documents and their versions, text read from them (including scanned pages), AI summaries and extracted details, projects, tasks, comments, chat messages, approvals and automations. This can include personal data about other people (for example names, emails, addresses or salaries in a document).
  • People outside your organization — when someone uses an upload or review link, the name, optional email, comment and decision they enter, and the files they upload.
  • Usage and security records — activity history (who did what, when), document audit trails, sign-in and error logs on our servers (which include IP address and browser), and AI usage counts.

We do not use advertising or analytics trackers. The apps keep your sign-in session in your browser’s local storage; this website sets no cookies.

Why we use it

  • To provide the service your organization signed up for: storing, reading, searching and organizing documents; running approvals and automations; sending notifications.
  • To keep it secure: authenticating people, preventing abuse, investigating problems.
  • To communicate with you about your account and the service.

Legal bases (where the GDPR applies): performance of our contract with your organization, our legitimate interest in running and securing the service, and legal obligations. We do not sell personal data, use it for advertising, or use your content to train AI models.

AI features

When your organization turns AI on, document text is sent to AI models on Amazon Bedrock in the United States to produce summaries, extracted details, tasks and answers. Amazon Bedrock does not store your content for its own purposes or use it to train models, and the model providers do not receive it. Admins can switch AI features off at any time.

Where it is stored

All data is stored and processed on Amazon Web Services in the US West (Oregon) region, us-west-2. AI requests may be processed in other AWS US regions. Data is encrypted in transit (HTTPS/TLS) and at rest. If you are outside the United States, your data is transferred to the US under the safeguards in our DPA (including the EU Standard Contractual Clauses where required).

Who processes it for us

We use a small number of service providers (“sub-processors”), listed with their purpose and location on our sub-processors page: Amazon Web Services (hosting, storage, email, text recognition, AI), Google and Microsoft (sign-in). Each is bound to protect the data and use it only to provide their service to us.

How long we keep it

DataKept
Documents, projects, tasks, commentsUntil your organization deletes them, or until the organization’s account is closed
Deleted documents (recycle bin)30 days, then permanently deleted
Automation run history30 days
Project activity history180 days
Server logs90 days
BackupsRolling 35 days (deleted data disappears from backups within 35 days)
Closed organizationsDeleted within 30 days of closing, on request sooner

Your rights and how to request deletion

You can ask to access, correct, export or delete your personal data, or object to or restrict its use. If your data is in a customer organization’s workspace, contact that organization’s admin first — they control that content and can remove you or your data. You can also write to privacy@projectonus-delivered.com; we will verify your identity, work with the organization where needed, and reply within 30 days. EU/UK residents can also complain to their data protection authority; California residents have the rights described in the CCPA/CPRA, and we do not sell or share personal information.

Children

ProjectOnUs is a business service and is not directed at children under 13. Schools using ProjectOnUs are responsible for having the consent needed for any student data they upload.

Security and breaches

See our security page. If a breach affects your personal data, we will notify the affected organization without undue delay and within 72 hours of becoming aware of it.

Changes

We will post changes here and, for significant ones, tell organization admins by email in advance.

✦ProjectOnUs
HomePricingFAQ Projects appContact PrivacyTermsDPASub-processorsSecurity
© 2026 ProjectOnUs